lano

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for a Membrane-managed Lano integration, and the CLI comes from npm rather than an opaque binary drop. However, it routes authentication and Lano API traffic through Membrane as an intermediary instead of directly to Lano, which materially expands the trust boundary and creates medium security risk despite not looking overtly malicious.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flano%2F@8e33067382ecfa867e77b944e5a41c7c763e4e63